Dissertação de Mestrado

SmartPasswords: Increasing Password Managers' Usability by Generating Compliant Passwords

João Miguel Pereira Campos2021

Informações chave

Autores:

João Miguel Pereira Campos (João Miguel Pereira Campos)

Orientadores:

João Fernando Peixoto Ferreira (João Fernando Peixoto Ferreira); Alexandra Sofia Ferreira Mendes

Publicado em

18/11/2021

Resumo

Passwords are still the go-to method to provide efficient user authentication in web applications, despite research showing that users usually choose weak passwords and reuse them across different services. Security experts advocate the usage of password managers. These tools can improve account security by enabling the utilization of unique and robust passwords, simultaneously improving the usability and convenience of text password authentication. However, these tools are not prepared to deal with overly restrictive password composition policies, which many websites employ. These policies pose challenges to password managers and may impact their usage: users become frustrated when generated passwords do not comply with such policies. We aim to solve this problem by 1) combining a language capable of describing password rules and a widely used password manager --- Bitwarden ---, and 2) expanding said language to express policies suggested by experts, which combine security and usability. We generated compliant passwords for every policy tested with our prototype, and Bitwarden accepted our solution to incorporate in their final product. These results are encouraging and suggest that password managers benefit from this ability to interpret password policies, which is a further step to increase the adoption of password managers.

Detalhes da publicação

Autores da comunidade :

Orientadores desta instituição:

Domínio Científico (FOS)

electrical-engineering-electronic-engineering-information-engineering - Engenharia Eletrotécnica, Eletrónica e Informática

Idioma da publicação (código ISO)

eng - Inglês

Acesso à publicação:

Embargo levantado

Data do fim do embargo:

09/10/2022

Nome da instituição

Instituto Superior Técnico